PT-2008-4578 · Novell · Novell Edirectory
Kingcope
·
Publicado
2008-07-14
·
Atualizado
2017-08-08
·
CVE-2008-3159
CVSS v2.0
10
Alta
| Vetor | AV:N/AC:L/Au:N/C:C/I:C/A:C |
Name of the Vulnerable Software and Affected Versions:
Novell eDirectory versions 8.7.3.10 through 8.7.3 SP10b
Novell eDirectory versions 8.8 through 8.8.2 ftf2
Description:
The issue is related to an integer overflow in ds.dlm, used by dhost.exe, which can lead to a stack-based buffer overflow. This is due to flawed arithmetic, allowing remote attackers to execute arbitrary code via unspecified vectors.
Recommendations:
For Novell eDirectory versions 8.7.3.10 through 8.7.3 SP10b, update to version 8.7.3 SP10b or later.
For Novell eDirectory versions 8.8 through 8.8.2 ftf2, update to version 8.8.2 ftf2 or later.
Correção
Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾
Enumeração de Fraquezas
Identificadores relacionados
Produtos afetados
Novell Edirectory